Unrated severityNVD Advisory· Published Jul 31, 2025· Updated Mar 23, 2026
ClipBucket <= 2.6 ofc_upload_image.php Arbitrary File Upload RCE
CVE-2013-10040
Description
ClipBucket version 2.6 and earlier contains a critical vulnerability in the ofc_upload_image.php script located at /admin_area/charts/ofc-library/. This endpoint allows unauthenticated users to upload arbitrary files, including executable PHP scripts. Once uploaded, the attacker can access the file via a predictable path and trigger remote code execution.
Affected products
1- Range: *
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- packetstorm.news/files/id/123480mitreexploit
- raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/unix/webapp/clipbucket_upload_exec.rbmitreexploit
- www.vulncheck.com/advisories/clipbucket-arbitrary-file-upload-rcemitrethird-party-advisory
- clipbucket.commitreproduct
News mentions
0No linked articles in our index yet.